# Fake brand-sponsorship and "channel verification" phishing campaign targets YouTube creators (Hollyland, Nike, Spotify impersonation)

> ESET reports a modular phishing scheme in which scammers send personalized sponsorship emails impersonating brands (Hollyland; Nike and Spotify variants), then steer YouTube creators to a fake collaboration platform that prompts a Google sign-in framed as channel ownership verification. The captured password and one-time code give attackers access to Gmail, Drive and the YouTube channel; in one reported case the victim's recovery phone and email were replaced and new backup codes generated.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3048
- **ID:** TL-2026-3048
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Scammers send personalized emails that reference the target creator's own videos and pose as a brand partnerships team. The primary lure impersonates Hollyland: a sender calling themselves "Brandi" from a supposed Creator Partnerships team offers a paid collaboration including a device and a long-term deal, from a sender domain unrelated to Hollyland. Nike and Spotify variants use near-identical sites. After the creator replies with their rates, the sender directs them to a fake collaboration platform to verify stats, the agreement and payment.

The platform is polished: it shows campaign metrics, major-company logos, an income calculator, and contract, joint-project and payment features. The creator submits their YouTube channel URL and the site pulls public channel data to personalize the experience. It then redirects to a Google sign-in step framed as verifying channel ownership. ESET describes an imposter login page that captures the password and the one-time code. The sites' social media icons link only to generic homepages, and the sites are built to pass a cursory inspection.

The operation is modular. Multiple branded fronts (MATCHY at joinmatchy[.]com and matchyjoin[.]com, SCOUTY at joinscouty[.]com, TUBIVE at mytubive[.]com) share favicons, meta descriptions and portions of source code, and domains and names were rotated repeatedly between June and August 2026. A further front, a fake agency called Creoventura (creoventura[.]com), was registered in August 2026 through Namecheap for one year with hidden ownership; it falsely lists AndaSeat, Hollyland and Maono as clients, and AndaSeat publicly stated it has no affiliation. The Creoventura name does not match the UK register entry ("Creoventure"), whose registered activities are IT and consultancy rather than influencer marketing.

Impact: access to the victim's Google account, including Gmail, Drive and the YouTube channel. One victim publicly reported that the attackers replaced her phone number and recovery email and generated new backup codes, locking her out. Victims have been reported in Peru (a journalist), Japan (YouTube support thread) and among English-speaking creators (Reddit). ESET names no actor, no kit and no malware, and does not state whether the capture is a live reverse proxy. Severity MEDIUM is an analyst judgment, not stated in the sources.

## MITRE ATT&CK

- T1583.001 Domains
- T1684.001 Impersonation
- T1566.002 Spearphishing Link
- T1598.003 Spearphishing Link
- T1204.001 Malicious Link
- T1056.003 Web Portal Capture
- T1111 Multi-Factor Authentication Interception
- T1078.004 Cloud Accounts
- T1098 Account Manipulation
- T1531 Account Access Removal

## Sources

- [ESET WeLiveSecurity: Inside a brand deal scam targeting YouTube creators](https://www.welivesecurity.com/en/social-media/brand-deal-scam-targeting-youtube-creators/)
- [Help Net Security: YouTubers targeted with fake sponsorships and "channel verification" phishing](https://www.helpnetsecurity.com/2026/10/08/scams-targeting-youtube-creators-sponsorship/)
- [AndaSeat statement disclaiming any affiliation with Creoventura](https://x.com/andaseatchair/status/2105628802260816151)
- [Google account recovery](https://accounts.google.com/signin/recovery)
- [Google Security Checkup](https://myaccount.google.com/security-checkup)
- [Infosecurity Magazine: YouTube Creators Targeted in Global Phishing Campaign (earlier, unrelated CloudSEK-reported creator campaign, for context)](https://www.infosecurity-magazine.com/news/youtube-creators-global-phishing/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3048
